Ransomware Virus you could lose all your photos documents etc

Discussion in 'Computer Corner' started by JWK, Sep 1, 2016.

  1. JWK

    JWK Gardener Staff Member

    Joined:
    Jun 3, 2008
    Messages:
    30,956
    Gender:
    Male
    Location:
    Surrey
    Ratings:
    +46,372
    Mrs JWK just got her laptop infected by a nasty virus which means she lost all her files.

    Basically this .Locky virus encrypts all your photos, music, videos, word documents, spreadsheets etc and demands a ransom for the key, which is £1,200+ in Bitcoins! There is no way to get these files back without paying.

    So I'm warning you to be on the lookout for it, don't open any email attachments unless you recognise and trust the sender. Mrs JWK knows this but somehow it got through. I've looked at her recent email and can't see anything suspicious, after a scan I can only lay the blame on Adware opening a back door.

    The virus (there are several) searches all your disks, mapped drives, Netware Attached Storage - even if you use cloud backup/sync services too. It even wipes out any shadow copies if you use that feature.

    The best protection is to back up, back up, back up to a removable USB disk - don't leave it attached as the virus will find it.

    The advice is to not pay the ransom to these crooks as it obviously encourages them and pays for the next generation of even more nasty stuff. It is quite likely the crooks will run off with the money anyway and who knows what this is funding? Apparently they are making huge sums as some businesses are paying up.

    Luckily Mrs JWK doesn't use her laptop for much apart from emails so she only lost a handful of files. It would have been a disaster if it had got onto my PC as that's where we keep all our family photo collection, over 16 years worth of irreplaceable digital images.
     
    • Informative Informative x 4
    • Friendly Friendly x 4
    • shiney

      shiney President, Grumpy Old Men's Club Staff Member

      Joined:
      Jul 3, 2006
      Messages:
      61,486
      Gender:
      Male
      Occupation:
      Retired - Last Century!!!
      Location:
      Herts/Essex border. Zone 8b
      Ratings:
      +118,842
      Thanks for the warning. :blue thumb:
       
      • Agree Agree x 1
      • Friendly Friendly x 1
      • Fat Controller

        Fat Controller 'Cuddly' Scottish Admin! Staff Member

        Joined:
        May 5, 2012
        Messages:
        26,530
        Gender:
        Male
        Occupation:
        Public Transport
        Location:
        At me 'puter, GCHQ Ashford Office, Middlesex
        Ratings:
        +49,789
        I would strongly recommend everyone to download and install Malwarebytes - it is a free program (there is a paid version with more features if you feel the need to), and it is fantastic at not only getting rid of ransomware but also at preventing it getting into your PC in the first place.

        Always remember - only open emails from known sources, and definitely DO NOT open any attachments, even if they claim to be invoices, bills or prize certificates.

        I generally always advise people to run Mozilla Firefox, for which there is an ad-blocker available to block adverts on sites that you do not trust - Adblock Ultimate is the best one because it allows you to 'whitelist' sites that you know and wish to support by allowing advertising (such as GC).

        If you are unfortunate enough to get a virus like this, the first thing is DO NOT PANIC, and DO NOT PAY ANYTHING!

        I have never come across a case yet where I have not been able to get shot of the viruses, without spending any money. Admittedly, this may well be very difficult to do remotely however I am more than happy to offer advice as to how to proceed, so please feel free to ask.

        @JWK - did the laptop get sorted, or can I help in any way?
         
        • Informative Informative x 3
        • shiney

          shiney President, Grumpy Old Men's Club Staff Member

          Joined:
          Jul 3, 2006
          Messages:
          61,486
          Gender:
          Male
          Occupation:
          Retired - Last Century!!!
          Location:
          Herts/Essex border. Zone 8b
          Ratings:
          +118,842
          @fat controller I seem to remember that the free version of Malwarebytes doesn't allow you to set it to scan automatically or update automatically. Does it still check everything that comes in?
           
          • Friendly Friendly x 1
          • Fat Controller

            Fat Controller 'Cuddly' Scottish Admin! Staff Member

            Joined:
            May 5, 2012
            Messages:
            26,530
            Gender:
            Male
            Occupation:
            Public Transport
            Location:
            At me 'puter, GCHQ Ashford Office, Middlesex
            Ratings:
            +49,789
            It doesn't scan automatically, but requires the user to run it periodically (the paid version does it automatically in the background); however, the manual scan coupled with a decent anti-virus program should see you remain clear of any problems.

            I am a big fan of Firefox being part of the 'suite' too, as the ad-block helps ensure that you are not bombarded with pop-up advert windows (they are the dangerous ones - you click on a perfectly legitimate link and it opens an advert window you don't see, and then that in turn opens a load more and before you know it you have a virus).

            It is no different to real life really, hygiene is all important - if you don't practice good hygiene you are going to get a nasty bug.
             
            • Agree Agree x 1
            • Informative Informative x 1
            • JWK

              JWK Gardener Staff Member

              Joined:
              Jun 3, 2008
              Messages:
              30,956
              Gender:
              Male
              Location:
              Surrey
              Ratings:
              +46,372
              Yes I sorted it Ok many thanks.

              There is no sign of the virus because after it has encrypted all user files and put the ransom message on the desktop it then deletes itself. The big problem is that the user files are unreadable and there is no known decrypter. If you don't have a backup you are stuffed.

              In our case I did a system restore followed by a "restore previous versions" in each folder. The .Locky virus normally deletes previous versions, luckily it failed this time so I didn't have to resort to our USB HDD archive. So Mrs JWK got all her files back although one was a couple of months out of date. No real harm done just a couple of hours wasted. It's made me think a lot more about the security of all our digital files and tighten up our backup regime.

              In particular I have been relying on a couple of NAS systems a freeware archive utility along with the excellent Windows 10 Time Machine feature. Now I realise my setup is vulnerable to these latest generation of crypto ransomware viruses.
               
              • Like Like x 1
              • Agree Agree x 1
              • shiney

                shiney President, Grumpy Old Men's Club Staff Member

                Joined:
                Jul 3, 2006
                Messages:
                61,486
                Gender:
                Male
                Occupation:
                Retired - Last Century!!!
                Location:
                Herts/Essex border. Zone 8b
                Ratings:
                +118,842
                I have Avast (set on automatic scans, three times a day, and automatic updates) but how often should I run Malwarebytes?
                 
                • Friendly Friendly x 1
                • shiney

                  shiney President, Grumpy Old Men's Club Staff Member

                  Joined:
                  Jul 3, 2006
                  Messages:
                  61,486
                  Gender:
                  Male
                  Occupation:
                  Retired - Last Century!!!
                  Location:
                  Herts/Essex border. Zone 8b
                  Ratings:
                  +118,842
                  I thought that if you didn't bother to wash then the smell would keep the bugs away. :lunapic 130165696578242 5:
                   
                  • Funny Funny x 3
                  • Fat Controller

                    Fat Controller 'Cuddly' Scottish Admin! Staff Member

                    Joined:
                    May 5, 2012
                    Messages:
                    26,530
                    Gender:
                    Male
                    Occupation:
                    Public Transport
                    Location:
                    At me 'puter, GCHQ Ashford Office, Middlesex
                    Ratings:
                    +49,789
                    I would say monthly, unless you have a notable problem (computer slow down or odd behaviour); Ccleaner is another excellent little program for clearing out the rubbish from your PC and keeping it running sweet. Again, run monthly is sufficient for most domestic PC's
                     
                    • Like Like x 2
                    • CanadianLori

                      CanadianLori Total Gardener

                      Joined:
                      Sep 20, 2015
                      Messages:
                      9,727
                      Occupation:
                      Battle Axe
                      Location:
                      Oakville, Ontario, Canada Zone 5A
                      Ratings:
                      +30,687
                      I never open email attachments without knowing the source.

                      And then there is the other type of alert.... Everybody wants to get together with me because I'm friendly.....and er, desirable. I'm no longer roping in gents to go out to see the bluebells so I know without looking at the source that it's a hoax :roflol:
                       
                      • Like Like x 3
                      • HarryS

                        HarryS Eternally Optimistic Gardener

                        Joined:
                        Aug 28, 2010
                        Messages:
                        8,906
                        Gender:
                        Male
                        Occupation:
                        Retired
                        Location:
                        Wigan
                        Ratings:
                        +16,247
                        Just updated Malwarebytes last weekend , and it seems to be checking for malicious websites. Could be just the free trial 30 day version ? Good tip to disconnect your external disc drive that I use for back up.
                         
                        • Like Like x 2
                        • clueless1

                          clueless1 member... yep, that's what I am:)

                          Joined:
                          Jan 8, 2008
                          Messages:
                          17,778
                          Gender:
                          Male
                          Location:
                          Here
                          Ratings:
                          +19,596
                          The virus writer's best friend is the person that leaves the default windows setup.

                          The default setup has you login automatically as administrator. That means any application you run automatically has full and unrestricted access to your entire system. One of the simplest security measures anyone can do is simply add a new user account, without superuser privileges, and use that as the default account. That way any stealth downloads are powerless to install anything or mess with anything without at least prompting you to ask for admin privileges.
                           
                          • Informative Informative x 3
                          • Like Like x 1
                          • Agree Agree x 1
                          • shiney

                            shiney President, Grumpy Old Men's Club Staff Member

                            Joined:
                            Jul 3, 2006
                            Messages:
                            61,486
                            Gender:
                            Male
                            Occupation:
                            Retired - Last Century!!!
                            Location:
                            Herts/Essex border. Zone 8b
                            Ratings:
                            +118,842
                            Ahh! My emails are still getting through. :thumbsup: :whistle: :loll:
                             
                            • Funny Funny x 2
                            • shiney

                              shiney President, Grumpy Old Men's Club Staff Member

                              Joined:
                              Jul 3, 2006
                              Messages:
                              61,486
                              Gender:
                              Male
                              Occupation:
                              Retired - Last Century!!!
                              Location:
                              Herts/Essex border. Zone 8b
                              Ratings:
                              +118,842
                              The trouble with that is that I don't understand a word you have said :dunno: :sad: :scratch:
                               
                              • Funny Funny x 4
                              • clueless1

                                clueless1 member... yep, that's what I am:)

                                Joined:
                                Jan 8, 2008
                                Messages:
                                17,778
                                Gender:
                                Male
                                Location:
                                Here
                                Ratings:
                                +19,596
                                And the trouble with Windows is that most of its users also don't understand that. It is marketed as an operating system that non-techies can use. In that respect it is seriously flawed in my opinion. It should either be left as is but marketed as a system requiring tech knowledge, which would reduce its popularity, or it should be changed to guide a non-techie to create and set as default a normal user account on first use.

                                To be entirely fair to Microsoft though, I don't think it's entirely their fault. When they do the OEM terms for pc and laptop builders they give too much freedom. The likes of dell and other names should configure their standard build correctly, but they won't because they don't want to add what is perceived as a layer of inconvenience for their customers. That layer of inconvenience being the cyber equivalent of the layer of inconvenience that most of us have on the main doors into our houses, ie locks that need a key to open them.
                                 
                                • Informative Informative x 2
                                • Like Like x 1
                                • Agree Agree x 1
                                  Last edited: Sep 2, 2016
                                Loading...

                                Share This Page

                                1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
                                  By continuing to use this site, you are consenting to our use of cookies.
                                  Dismiss Notice